You administer Windows 10 Enterprise laptop and desktop computers. Your company uses Active Directory
Domain Services (AD DS) and Active Directory Certificate Services (AD CS).
Your company decides that access to the company network for all users must be controlled by two-factor
authentication.
You need to configure the computers to meet this requirement. What should you do?
A.
Install smart card readers on all computers. Issue smart cards to all users.
B.
Enable the Password must meet complexity requirements policy setting. Instruct users to logon by typing
their user principal name (UPN) and their strong password.
C.
Create an Internet Protocol security (IPsec) policy on each Windows 10 Enterprise computer to encrypt
traffic to and from the domain controller.
D.
Issue photo identification to all users. Instruct all users to create and use a picture password.
Explanation:
Smart cards contain a microcomputer and a small amount of memory, and they provide secure, tamper-proof
storage for private keys and X.509 securitycertificates.
A smart card is a form of two-factor authentication that requires the user to have a smart card and know the
PIN to gain access to network resources.